Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
1–10 of 166 posts
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#2Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#3Having prefaced my response with the above clarification, such an outcome should be expected rather than being unexpected. There's no such thing as a totally secure and uncompromisable system. Any system can be compromised. Where there's a system, there's a way to compromise it.
When all is said and done, what can reasonably be expected is a system that's as secure as it can be reasonably made and a genuine effort to patch vulnerabilities as quickly as humanly possible.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#4"The by far most expensive part of the iris biometry hack was the purchase of the Galaxy S8 smartphone."
You can tell they really had fun with this!
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#5Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#6Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#7This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#8That's not quite true, Lumia 950, Lumia 950 XL and HP Elite x3 came out a lot earlier than the Galaxy S8 and all of them use iris recognition (still undefeated, by the way)
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#9Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter.
Also, multi-spectral is a pretty good test, though I don't know enough about the capabilities of the S8 camera to know if that's feasible (shouldn't be that hard.) Capturing the patterns of the iris at 500, 800, and 1200nm results in three templates that are quite different from another.
CCC were able to do this for about the cost of a S8. I would say this is one of the rare situations where defeating the attack would have been even cheaper. It's that simple a programming exercise.
Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8
#10Whilst it's certainly valuable to make people aware of the limitations of the security systems we use, this shouldn't really come as a surpre. If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode - sure, you might do that less often, but for an average user are either of those thi…
It shows again that for people with very valuable data (where others would spend significant amounts of money to get data), passwords remain the only secure way.